Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-7539

Опубликовано: 16 мая 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-7539: ruby:2.5 security update (MODERATE)

ruby [2.5.9-114]

  • Fix integer overflow in search_in_range function in regexec.c (CVE-2019-19012). Resolves: RHEL-87505

rubygem-abrt rubygem-bson rubygem-bundler [1.16.1-5]

  • Fix unexpected code execution in Gemfiles (CVE-2021-43809) Resolves: RHEL-87017

rubygem-mongo rubygem-mysql2 rubygem-pg

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

Module ruby:2.5 is enabled

ruby

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-devel

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-doc

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-irb

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-libs

2.5.9-114.module+el8.10.0+90580+29305b94

rubygem-abrt

0.3.0-4.module+el8.10.0+90367+ae9e8511

rubygem-abrt-doc

0.3.0-4.module+el8.10.0+90367+ae9e8511

rubygem-bigdecimal

1.3.4-114.module+el8.10.0+90580+29305b94

rubygem-bundler

1.16.1-5.module+el8.10.0+90580+29305b94

rubygem-bundler-doc

1.16.1-5.module+el8.10.0+90580+29305b94

rubygem-did_you_mean

1.2.0-114.module+el8.10.0+90580+29305b94

rubygem-io-console

0.4.6-114.module+el8.10.0+90580+29305b94

rubygem-json

2.1.0-114.module+el8.10.0+90580+29305b94

rubygem-minitest

5.10.3-114.module+el8.10.0+90580+29305b94

rubygem-mongo

2.5.1-2.module+el8.9.0+90042+a65659a6

rubygem-net-telnet

0.1.1-114.module+el8.10.0+90580+29305b94

rubygem-openssl

2.1.2-114.module+el8.10.0+90580+29305b94

rubygem-power_assert

1.1.1-114.module+el8.10.0+90580+29305b94

rubygem-psych

3.0.2-114.module+el8.10.0+90580+29305b94

rubygem-rake

12.3.3-114.module+el8.10.0+90580+29305b94

rubygem-rdoc

6.0.1.1-114.module+el8.10.0+90580+29305b94

rubygem-test-unit

3.2.7-114.module+el8.10.0+90580+29305b94

rubygem-xmlrpc

0.3.0-114.module+el8.10.0+90580+29305b94

rubygems

2.7.6.3-114.module+el8.10.0+90580+29305b94

rubygems-devel

2.7.6.3-114.module+el8.10.0+90580+29305b94

rubygem-bson

4.3.0-2.module+el8.9.0+90042+a65659a6

rubygem-bson-doc

4.3.0-2.module+el8.9.0+90042+a65659a6

rubygem-mongo-doc

2.5.1-2.module+el8.9.0+90042+a65659a6

rubygem-mysql2

0.4.10-4.module+el8.9.0+90042+a65659a6

rubygem-mysql2-doc

0.4.10-4.module+el8.9.0+90042+a65659a6

rubygem-pg

1.0.0-3.module+el8.9.0+90042+a65659a6

rubygem-pg-doc

1.0.0-3.module+el8.9.0+90042+a65659a6

Oracle Linux x86_64

Module ruby:2.5 is enabled

ruby

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-devel

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-doc

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-irb

2.5.9-114.module+el8.10.0+90580+29305b94

ruby-libs

2.5.9-114.module+el8.10.0+90580+29305b94

rubygem-abrt

0.3.0-4.module+el8.10.0+90367+ae9e8511

rubygem-abrt-doc

0.3.0-4.module+el8.10.0+90367+ae9e8511

rubygem-bigdecimal

1.3.4-114.module+el8.10.0+90580+29305b94

rubygem-bundler

1.16.1-5.module+el8.10.0+90580+29305b94

rubygem-bundler-doc

1.16.1-5.module+el8.10.0+90580+29305b94

rubygem-did_you_mean

1.2.0-114.module+el8.10.0+90580+29305b94

rubygem-io-console

0.4.6-114.module+el8.10.0+90580+29305b94

rubygem-json

2.1.0-114.module+el8.10.0+90580+29305b94

rubygem-minitest

5.10.3-114.module+el8.10.0+90580+29305b94

rubygem-net-telnet

0.1.1-114.module+el8.10.0+90580+29305b94

rubygem-openssl

2.1.2-114.module+el8.10.0+90580+29305b94

rubygem-power_assert

1.1.1-114.module+el8.10.0+90580+29305b94

rubygem-psych

3.0.2-114.module+el8.10.0+90580+29305b94

rubygem-rake

12.3.3-114.module+el8.10.0+90580+29305b94

rubygem-rdoc

6.0.1.1-114.module+el8.10.0+90580+29305b94

rubygem-test-unit

3.2.7-114.module+el8.10.0+90580+29305b94

rubygem-xmlrpc

0.3.0-114.module+el8.10.0+90580+29305b94

rubygems

2.7.6.3-114.module+el8.10.0+90580+29305b94

rubygems-devel

2.7.6.3-114.module+el8.10.0+90580+29305b94

rubygem-bson

4.3.0-2.module+el8.9.0+90042+a65659a6

rubygem-bson-doc

4.3.0-2.module+el8.9.0+90042+a65659a6

rubygem-mongo

2.5.1-2.module+el8.9.0+90042+a65659a6

rubygem-mongo-doc

2.5.1-2.module+el8.9.0+90042+a65659a6

rubygem-mysql2

0.4.10-4.module+el8.9.0+90042+a65659a6

rubygem-mysql2-doc

0.4.10-4.module+el8.9.0+90042+a65659a6

rubygem-pg

1.0.0-3.module+el8.9.0+90042+a65659a6

rubygem-pg-doc

1.0.0-3.module+el8.9.0+90042+a65659a6

Связанные CVE

Связанные уязвимости

rocky
около 1 года назад

Moderate: ruby:2.5 security update

CVSS3: 9.8
ubuntu
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

CVSS3: 7.5
redhat
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

CVSS3: 9.8
nvd
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

CVSS3: 9.8
debian
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in On ...